Skip to content

chore(deps)(deps-dev): bump @types/node from 20.19.30 to 25.0.10 - #195

Merged
hotlong merged 7 commits into
mainfrom
dependabot/npm_and_yarn/types/node-25.0.10
Feb 1, 2026
Merged

hotlong merged 7 commits into
mainfrom
dependabot/npm_and_yarn/types/node-25.0.10

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jan 26, 2026 •

Copy link
Copy Markdown
Contributor

Bumps @types/node from 20.19.30 to 25.0.10.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript labels Jan 26, 2026
@vercel

vercel Bot commented Jan 26, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
spec Ready Ready Preview, Comment Feb 1, 2026 3:47am

Request Review

@github-actions github-actions Bot added documentation Improvements or additions to documentation size/s labels Jan 26, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/types/node-25.0.10 branch from 4c509ed to 8195f5b Compare January 26, 2026 12:37
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/types/node-25.0.10 branch from 8195f5b to e338f14 Compare January 27, 2026 03:48
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/types/node-25.0.10 branch from e338f14 to 1af5186 Compare January 27, 2026 09:38
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/types/node-25.0.10 branch from 1af5186 to 9360fc1 Compare January 28, 2026 05:29
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/types/node-25.0.10 branch from 9360fc1 to f83d66b Compare January 28, 2026 05:40
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/types/node-25.0.10 branch from f83d66b to 7d094dc Compare January 28, 2026 09:59
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/types/node-25.0.10 branch from 7d094dc to 55b1001 Compare January 28, 2026 10:27
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 20.19.30 to 25.0.10.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 25.0.10
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/types/node-25.0.10 branch from dd57d39 to 73467e1 Compare February 1, 2026 02:49
…in examples/basic

Co-authored-by: hotlong <50353452+hotlong@users.noreply.github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/types/node-25.0.10 branch from 73467e1 to 5813a7a Compare February 1, 2026 03:05
hotlong and others added 2 commits February 1, 2026 11:06
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 20.19.30 to 25.0.10.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 25.0.10
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@hotlong
hotlong merged commit f482e8c into main Feb 1, 2026
11 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/types/node-25.0.10 branch February 1, 2026 03:48
akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Sep 28, 2026
…n the commit sha — and runtime strings carry no tracker number (objectstack-ai#19453)

Fixes objectstack-ai#19294

Clause-②: no

AGENTS.md's register paragraph told every agent that a rule's provenance
lives in the PR that landed it. Merged-PR numbers decay out of GitHub —
the spec seat measured 11.7 %–15.1 % of one week's already deleted, with
no 301 and an empty commit-to-PR association — so that convention
pointed every reader at objects this repository does not control and has
measured itself destroying. The maintainer ruled the replacement
(decision batch objectstack-ai#195 item 3 letter C+D, verbatim and untranslated: 「同意」;
the director recorded it on the card this PR lands on). The sentence is
REPLACED, not appended to: no second convention survives beside it.

`grep -n -iE 'provenance|PR that landed|landed it' AGENTS.md` on 57ceb9d
returns two hits — the sentence at :14 and, at :253, the unrelated
instruction that a repo-local ADR mirroring a cloud decision carries a
`## Provenance` section. The convention is stated once, so one sentence
is replaced and nothing else in the file restates it.

## Before / after — AGENTS.md :14, against 57ceb9d

Before:

```text
(`pnpm check:pm-skill-id-lint`) — a rule's provenance lives in the PR that landed it. Where
a hook or CI gate enforces a rule mechanically, the rule is stated once here and the
script's own header is the authority on detail.
```

After:

```text
(`pnpm check:pm-skill-id-lint`) — a rule's provenance cites the ADR or ruling record that
decided it, otherwise the commit sha in this repository's history; a PR number is a
convenience link, ⛔ never the citation. Runtime strings — refusal prose, prescriptions,
anything an author is shown — carry no tracker number (`pnpm check:doc-authoring`): the
lesson goes into the text. Where a hook or CI gate enforces a rule mechanically, the rule is
stated once here and the script's own header is the authority on detail.
```

The ruled clauses land in the ruling's own order: the ADR or ruling
record first (stable, in-repo, it carries the narrative); otherwise the
commit sha in this repository's history (immutable, and `git` reads it
with no network); a PR number demoted to a convenience link and ⛔ never
the citation. Letter D is the sentence after it — runtime strings carry
no tracker number, under the maintainer's standing words 「处理 issue
时犯的错应该总结成经验,保留 issue id没有意义」: the lesson is written into the text
instead of a number the reader must dereference.

The neighbouring clause about mechanical enforcement is kept intact, and
the new text obeys itself — it carries no bare tracker number, and `pnpm
check:pm-skill-id-lint`, which scans AGENTS.md against the pattern it
names, is green on it.

Stated precisely rather than implied: the gate cited for letter D
reaches `packages/` minus `packages/spec` today, on a shrink-only
baseline of 821 pinned sites across 231 files. The prose states the
repo-wide rule; extending the gate's reach is the separate card already
named on the issue body, not this one.

## The AGENTS.md line ratchet — paid at net 0, the ceiling untouched

The ruled text is +3 physical lines and AGENTS.md sat at headroom 0
(1099 / 1099), so the first head (9f35c66) measured `pnpm
check:pm-skill-ratchet :: exit 1`. The seat widened this card's file
surface so the three lines are paid in RETIRED CONTENT — each retired
fragment is a verbatim restatement of a rule whose home is another line,
or a second pointer to a file already pointed at from a surviving line —
⛔ never by raising the ceiling (the CEILINGS row in
`scripts/pm/check-skill-line-ratchet.mjs` is untouched at 1099). Head
a799442: AGENTS.md 1099 → 1099, `pnpm check:pm-skill-ratchet :: exit 0`.

| retired (pre-edit line) | what it was | the rule still lives at |
|:--|:--|:--|
| :58–59 「; the script headers are the authority on detail」 |
restatement | :19 — the register paragraph's own clause; the two gates
it qualified stay named on the line |
| :452–453 「The two measured mutation shapes and their triggers live in
pm-dispatch `references/platform-readings.md`.」 | second pointer |
:433–434, two paragraphs above in the same section |
| :758–759 「(shape, sha256 vs that record, record pin ==
`.objectui-sha`)」 | the gate's detail list | :19 (the script's own
header is the authority on detail); `scripts/check-sdui-manifest.mjs`
stays named; the regenerate-on-pin-bump rule at :159–161 |
| :760–761 「— "could not run" is a failure, not a skip (Route & surface
ownership §3) —」 | restatement + second pointer | :851–855, Route &
surface ownership rule 3 |

All three lines are bought by deleted content, none by re-wrap: each
untouched paragraph greedy-wraps to exactly the line count it already
had. Candidates rejected and why (an only pointer; PR objectstack-ai#19214's reserved
region :931–:956; fragments that buy no line; a loosely wrapped
paragraph whose lines would be re-wrap currency; gate-pinned
governed-surface enumerations) are on the card's second `os-dev-report`.

## Verification

Derived union on a799442 (re-run after the retirements and one merge of
`origin/main`), `node scripts/pm/dispatch-gates.mjs --commands --repo
objectstack-ai/objectstack` with no paths, reconciled with `--ran`: **15
derived, 15 run, 0 NOT-MEASURED, 0 UNRUN**, every exit captured before
any pipe.

Green (15): `check-closing-keyword-parity` (gate and `--self-test`),
`check-comment-mask-corpus`, `check:agent-test-spelling`,
`check:docs-audit-scope`, `check:driver-memory-census`,
`check:gitlink-declared`, `check:nul-bytes`, `check:pm-governed-merges`,
`check:pm-governed-prose`, `check:pm-skill-id-lint`,
`check:refd-timer-probe`, `check:required-contexts`,
`check:watch-hint-literal`, `check:pm-skill-ratchet` (AGENTS.md 1099
lines, ceiling 1099, headroom 0).

Run beyond the union because the new text names it: `pnpm
check:doc-authoring :: exit 0` — 403 files clean, 44 published skill
files clean, 15881 customer-facing strings across 1013 spec sources
clean, sibling-package prose ids holding the baseline.

No package is touched, so there is no dependency closure to build and no
package test suite in scope; the repo-wide `pnpm lint` scan is CI's run,
not this PR's. `skip-changeset`: AGENTS.md is a repo-root instruction
file and ships in no package's `files[]`.

## Acceptance notes

- Noted, not filed: the gate cited for letter D excludes `packages/spec`
from its prose-id leg and runs on a shrink-only baseline, so the
mechanical reach is narrower than the prose rule. Carrier: the reach
card already named on the issue body — no new card.
- Noted, not filed: the CEILINGS row for AGENTS.md now carries four
stacked per-card narratives in a gate script whose own header prescribes
moving narrative out of operational text. Carrier: the next ceiling
raise on that row, PR objectstack-ai#19214, already in flight.

## 维护者速读(草稿)

**改了什么** — AGENTS.md 开头「规则登记册」那一段里的一句:规则的出处从「落地它的 PR」改成「先引 ADR /
裁决记录,没有就引本仓的 commit sha,PR
号只能当顺手链接」;并补上一句「运行时字符串(拒绝文案、处方、任何打给作者看的文字)不带任何 issue
号,把教训写进正文」。这三行的增量由退掉文件里四处重复陈述 / 重复指针付账(上表),文件净 0 行,行数棘轮上限没动。

**为什么改** — 旧写法把读者指向 GitHub 上的 PR 号,而实测一周内已合并 PR 号有 11.7%–15.1% 已经被删除(没有
301,commit 到 PR 的关联是空的)。也就是说,规则的出处指向了一个本仓库不拥有、而且已经被测到正在消失的对象。ADR / 裁决记录和
commit sha 都在仓库里,不会消失。这是您在裁决批次 objectstack-ai#195 第 3 项 C+D 上批的「同意」。

**风险与代价(含回滚)** — 风险很低:改的是一句给 AI 和人看的约定,没有代码、没有发布面、没有
changeset。代价是退掉的四处重复文字,每一处的规则仍住在上表点名的行;若您认为哪一处不该退,恢复它是一行
revert,但要同时退别的一行才能过棘轮。回滚就是 revert 这一个 commit,没有任何下游依赖。

**席位意见** — (留空,席位复审时定稿)

**你要做的** — 一件事:确认正文措辞后点合并(Tier H,这个 PR 一直是 draft,席位已做
ACCEPT;棘轮已绿,不需要您裁行预算)。


---
_Generated by [Claude Code](https://claude.ai/code)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Sep 28, 2026
…s reopen condition (objectstack-ai#19653)

Fixes objectstack-ai#18374

## 维护者速读(草稿)

**改了什么** —— ADR-0090 D10 的 `agent` 规则 4 要求每次 agent
写入记三样:谁干的、代谁干的、**哪一次运行**。前两样已在产,第三样没有。本 PR 在该决策自己的注记尾部(规则 4
已经指过去的那处)加一条带日期的状态行 —— 13 行、一个文件 —— 写明「运行 id 未交付」、为什么、以及它什么时候该回来:任务级
agent 授权落地时,**授权 id 就是运行 id**。⛔ 规则 4 自己那句话一个字没动。

**为什么改** —— 执行裁决评论 `5749155184`(总监席 batch objectstack-ai#195 item 2,letter
**C**,维护者「同意」2026-09-20)。一条声明了却发不出来的契约,比一条写明「暂缓」的契约更糟;ADR-0049
的诚实状态那一档要求把它标成未交付,而不是随手铸一个「叫运行 id 的请求 id」。

**风险与代价(含回滚)** —— 纯文档:零运行时、零 spec、零发布面。回滚 = revert
这一个提交。真正的代价是未来读者会看到一条明写「未交付」的规则 —— 这正是目的,而不是副作用。

**席位意见** —— 技能席 1(`session_01Wnstp2kTth7sGXfr8fXypc`)已按 GitHub 与拉取的 head
`495929b` 复核:13 行与裁决 5749155184 的五项内容逐一对应(已交付对、run id 未交付、两条 why、reopen
条件、裁决引用),规则 4 原句一字未动,注记落在规则 4
自己指向的注记尾部;`check-adr-symbol-anchors`、`check-adr-links`、`check:adr-anchors`
在本席自己的 worktree 复跑均 exit 0,`check-governed-merges --pr 19653` 读 GOVERNED
Tier H(13 行)。两处对派发词的修正本席认可:docblock 只留位、未命名 `runId`,注记如实写「留位不留名」;+13
行超出派发词的 ≤ +5 系派发词自相矛盾(内容清单与行数上限在 100 列换行下不可能同时成立),内容优先。建议合并;`Fixes
objectstack-ai#18374` 合入即关卡,`pm:dispatched` 由本席在合入时摘。

**你要做的(一个动作)** —— 读那 13 行,认可就手工合并。`docs/adr/**` 是 Tier H 受管面,本 PR 保持
draft,⛔ 没有 AI 席位可以代你合、代你入队或给它挂 auto-merge。

Clause-②: no

## What landed

One dated status note in
`docs/adr/0090-permission-model-v2-concept-convergence.md` — **13 lines
added, 0 removed, 1 file**. It sits in the decision's own note tail,
immediately after the 2026-09-16 note that rule 4's own sentence already
points readers at ("see the 2026-09-16 note at the end of this
decision"), so both amendments to rule 4 now live in one place, in date
order. Rule 4's sentence is byte-unchanged.

The note states, in the ruling's order: `performed_by` and
`on_behalf_of` ship (objectstack-ai#18371); no run id is stamped and none is pending;
why (no agent-run concept on the request path — the MCP door is
explicitly stateless — so no server-constructed identifier grouping one
agent task exists to carry, and the two correlation ids that do travel
that path, `traceId` from the client's `traceparent` and `requestId`
preferring the client's `X-Request-Id`, are caller-controlled, which the
envelope refuses in writing); the reopen condition (task-scoped,
time-boxed agent grants land ⇒ the grant id is the run id ⇒ a successor
wires `performedBy.runId`); and the ruling reference in the file's own
`Ruling:` form.

## Two measured corrections to the dispatch's premises

**The shipped docblock reserves the ROOM, not the NAME.**
`packages/spec/src/kernel/execution-context.zod.ts#performedBy` reads
verbatim: "A one-key object rather than a bare string so the API-key
door (objectstack-ai#18335, blocked on this carrier) can name its own identifier as a
sibling key if it is ruled an agent, without re-shaping a field that
already shipped." It reserves a sibling-key extension point and names
the API-key door as the motivating case; it never names `runId`. The
status note is worded to match what is actually reserved and says so
explicitly ("it reserves the room, ⛔ not the name") — writing it any
other way would have put a fresh declared-but-absent key into an ADR
whose whole point is that class of defect.

**The line budget could not hold the enumerated content.** The
dispatch's suggested route asked for net ≤ +5 physical lines *and*
enumerated five required contents; at this file's 100-column wrap those
two cannot both hold (the content is ~1,150 characters ≈ 12 wrapped
lines). Content won, lines were minimised: 13 added lines, every one of
them ≤ 100 columns, no line removed, nothing else in the tree touched.

## Gates

Derived mechanically, not recalled: `node scripts/pm/dispatch-gates.mjs
--repo objectstack-ai/objectstack --commands` (no paths — the script
took its own change set from the merge base), 19 families. All 19 run,
all exit 0, reconciled with `--ran`:

`✓ dispatch-gates --ran: 19 derived famil(ies) accounted for — 19 run, 0
NOT-MEASURED (a DERIVED zero — all 19 recorded an exit code and none of
them is 3).`

Named readings from that set:

- `node scripts/check-adr-symbol-anchors.mjs` :: exit 0 — `✅
check-adr-symbol-anchors: 2121 anchors across 140 records resolve`
- `pnpm check:doc-authoring` :: exit 0
- `pnpm check:adr-anchors` :: exit 0
- `pnpm check:pm-governed-merges` :: exit 0
- `pnpm check:nul-bytes` :: exit 0 (plus a hand scan of the inserted
text for control bytes: no match)

One family needed a prerequisite: `pnpm --filter @objectstack/lint run
check:doc-formula-expressions` first exited **3** — its own text says
"Nothing was measured: this gate exited before running a single check",
naming two unbuilt workspace packages. After `pnpm exec turbo run build
--filter=@objectstack/formula --filter=@objectstack/lint` (through
`scripts/pm/os-verify-lock.sh`, `VERDICT command-exit 0`) it re-ran at
**exit 0**. The exit-3 reading is recorded as NOT MEASURED, ⛔ not as a
failure.

Repo-wide scans (`pnpm lint` and the rest) are CI's run, not this PR's;
the type-check lanes and the path-scheduled CI job the derivation
printed as NOT MEASURED are CI's too.

## Reverse verification — the new citation is actually checked

The note cites
`packages/spec/src/kernel/execution-context.zod.ts#performedBy`, and
`check-adr-symbol-anchors` resolves that spelling. A green gate over a
corpus of 2121 anchors says nothing about *this* one, so it was ablated:
`node scripts/ablation-replace.mjs` swapped the symbol for
`ablationProbeNoSuchSymbol` (anchor hit 1 → 0, blob `27197b6cd90d` →
`978fa39ca89f`, both verified on disk by the tool, not by an exit code),
then re-ran the gate.

Predicted direction: turns red naming this line. Observed:

```
❌ check-adr-symbol-anchors: 1 finding(s) across 140 records.
  [unresolved-symbol] docs/adr/0090-permission-model-v2-concept-convergence.md:455  `packages/spec/src/kernel/execution-context.zod.ts#ablationProbeNoSuchSymbol`
      `ablationProbeNoSuchSymbol` has no declaration site or string-literal token in `packages/spec/src/kernel/execution-context.zod.ts`
```

Restore leg: `ablation-replace: ok restored: blob == HEAD (27197b6)
and 'git diff HEAD' is empty`. Both legs ran from the committed state;
no probe file survives. (A first attempt was refused by the tool because
the replacement text still contained the anchor as a substring, so the
anchor count did not drop — recorded here because that attempt measured
nothing.)

## Changeset — `skip-changeset`, measured

`docs/adr/**` publishes nothing. Measured rather than assumed: of 83
tracked `package.json` files, **70 declare `files[]` and none of them
ships `docs/`**; the 13 that declare no `files[]` are **all `private:
true`**. The single `files[]` entry a `docs|adr|**` probe matched is
`packages/spec` shipping `src/**/*.zod.ts`, which is not a docs path.

## Landing posture — Tier H, stays draft

`docs/adr/**` is Tier H (人合) on the `GOVERNED_SURFACES` register in
`scripts/pm/check-governed-merges.mjs`. This PR is opened draft and
stays draft: the maintainer merges it by hand. ⛔ No AI seat merges it,
queues it, arms auto-merge on it, flips it out of draft, or submits an
approving review on it.

## Acceptance notes

- The zero-commit remote branch
`claude/issue-18374-run-id-entry-carrier` (`564ac2f170`, the
`domain:spec` seat's write-path probe) is still on the remote. It is a
**stale marker, not in-flight work**. Comment `5753761987` measured both
delete channels refused (`git push --delete` hung up, REST `DELETE
/git/refs/...` answered 403), so this run did ⛔ not re-attempt the
delete.
- Observation only, ⛔ no card filed: the 2026-07 status blockquote at
the top of D10 tracks "the agent audit-provenance gap" as a follow-up
with **no tracker number beside it**, unlike the `objectstack-ai#2849` in the same
sentence. The status note this PR adds is that follow-up's record, but
the 2026-07 line was left untouched — amending it is outside this card's
declared file surface, and it is not a defect, a contract violation or a
metadata-authoring trap.
- Concurrency re-checked at this branch's base: all 18 open PRs' file
lists read; none touches
`docs/adr/0090-permission-model-v2-concept-convergence.md`.
`origin/main` had not moved from `80ca0b1c88`, so no merge was owed.


---
_Generated by [Claude Code](https://claude.ai/code)_

Co-authored-by: Claude <noreply@anthropic.com>

This branch was successfully deployed

1 active deployment
Preview — db5cb328 Deployed Feb 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file documentation Improvements or additions to documentation size/s

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants